Mandrake Linux Security Advisory : openoffice.org (MDKSA-2007:144)

high Nessus Plugin ID 25697

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

A heap overflow flaw was found in the RTF import filter of OpenOffice.org. If a victim were to open a specially crafted RTF file, OpenOffice.org could crash or possibly execute arbitrary code.

Updated packages have been patched to prevent the above issues.

Solution

Update the affected packages.

Plugin Details

Severity: High

ID: 25697

File Name: mandrake_MDKSA-2007-144.nasl

Version: 1.21

Type: local

Published: 7/11/2007

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:openoffice.org, p-cpe:/a:mandriva:linux:openoffice.org-devel, p-cpe:/a:mandriva:linux:openoffice.org-devel-doc, p-cpe:/a:mandriva:linux:openoffice.org-galleries, p-cpe:/a:mandriva:linux:openoffice.org-gnome, p-cpe:/a:mandriva:linux:openoffice.org-kde, p-cpe:/a:mandriva:linux:openoffice.org-l10n-af, p-cpe:/a:mandriva:linux:openoffice.org-l10n-ar, p-cpe:/a:mandriva:linux:openoffice.org-l10n-bg, p-cpe:/a:mandriva:linux:openoffice.org-l10n-br, p-cpe:/a:mandriva:linux:openoffice.org-l10n-bs, p-cpe:/a:mandriva:linux:openoffice.org-l10n-ca, p-cpe:/a:mandriva:linux:openoffice.org-l10n-cs, p-cpe:/a:mandriva:linux:openoffice.org-l10n-cy, p-cpe:/a:mandriva:linux:openoffice.org-l10n-da, p-cpe:/a:mandriva:linux:openoffice.org-l10n-de, p-cpe:/a:mandriva:linux:openoffice.org-l10n-el, p-cpe:/a:mandriva:linux:openoffice.org-l10n-en_gb, p-cpe:/a:mandriva:linux:openoffice.org-l10n-es, p-cpe:/a:mandriva:linux:openoffice.org-l10n-et, p-cpe:/a:mandriva:linux:openoffice.org-l10n-eu, p-cpe:/a:mandriva:linux:openoffice.org-l10n-fi, p-cpe:/a:mandriva:linux:openoffice.org-l10n-fr, p-cpe:/a:mandriva:linux:openoffice.org-l10n-he, p-cpe:/a:mandriva:linux:openoffice.org-l10n-hi, p-cpe:/a:mandriva:linux:openoffice.org-l10n-hu, p-cpe:/a:mandriva:linux:openoffice.org-l10n-it, p-cpe:/a:mandriva:linux:openoffice.org-l10n-ja, p-cpe:/a:mandriva:linux:openoffice.org-l10n-ko, p-cpe:/a:mandriva:linux:openoffice.org-l10n-mk, p-cpe:/a:mandriva:linux:openoffice.org-l10n-nb, p-cpe:/a:mandriva:linux:openoffice.org-l10n-nl, p-cpe:/a:mandriva:linux:openoffice.org-l10n-nn, p-cpe:/a:mandriva:linux:openoffice.org-l10n-pl, p-cpe:/a:mandriva:linux:openoffice.org-l10n-pt, p-cpe:/a:mandriva:linux:openoffice.org-l10n-pt_br, p-cpe:/a:mandriva:linux:openoffice.org-l10n-ru, p-cpe:/a:mandriva:linux:openoffice.org-l10n-sk, p-cpe:/a:mandriva:linux:openoffice.org-l10n-sl, p-cpe:/a:mandriva:linux:openoffice.org-l10n-sv, p-cpe:/a:mandriva:linux:openoffice.org-l10n-ta, p-cpe:/a:mandriva:linux:openoffice.org-l10n-tr, p-cpe:/a:mandriva:linux:openoffice.org-l10n-zh_cn, p-cpe:/a:mandriva:linux:openoffice.org-l10n-zh_tw, p-cpe:/a:mandriva:linux:openoffice.org-l10n-zu, p-cpe:/a:mandriva:linux:openoffice.org-mimelnk, p-cpe:/a:mandriva:linux:openoffice.org-mono, p-cpe:/a:mandriva:linux:openoffice.org-ooqstart, p-cpe:/a:mandriva:linux:openoffice.org64, p-cpe:/a:mandriva:linux:openoffice.org64-devel, p-cpe:/a:mandriva:linux:openoffice.org64-devel-doc, p-cpe:/a:mandriva:linux:openoffice.org64-galleries, p-cpe:/a:mandriva:linux:openoffice.org64-gnome, p-cpe:/a:mandriva:linux:openoffice.org64-kde, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-af, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-ar, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-bg, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-br, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-bs, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-ca, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-cs, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-cy, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-da, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-de, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-el, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-en_gb, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-es, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-et, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-eu, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-fi, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-fr, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-he, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-hi, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-hu, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-it, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-ja, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-ko, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-mk, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-nb, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-nl, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-nn, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-pl, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-pt, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-pt_br, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-ru, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-sk, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-sl, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-sv, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-ta, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-tr, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-zh_cn, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-zh_tw, p-cpe:/a:mandriva:linux:openoffice.org64-l10n-zu, p-cpe:/a:mandriva:linux:openoffice.org64-mono, p-cpe:/a:mandriva:linux:openoffice.org64-ooqstart, cpe:/o:mandriva:linux:2007, cpe:/o:mandriva:linux:2007.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/10/2007

Reference Information

CVE: CVE-2007-0245

BID: 24450

CWE: 119

MDKSA: 2007:144